Extension WordPress
Vulnérabilités Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Cette page rassemble les failles publiées pour Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
73 fiches
Ultimate Member <= 2.11.4 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'about_me' parameter in all versions up to, and including, 2.11.4 due to…
*-2.11.4
2.12.0
02/07/2026
Ultimate Member <= 2.11.4 – Authenticated (Contributor+) Account Takeover via Password Reset Link Disclosure
The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.11.4. This is due to a chain of three logic bugs: (1) an MD5 hash…
*-2.11.4
2.12.0
23/06/2026
Ultimate Member <= 2.11.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting via DOM Gadgets
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all versions up to, and including, 2.11.1 due…
*-2.11.1
2.11.2
03/04/2026
Ultimate Member <= 2.11.2 – Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[um_loggedin]' shortcode, which…
*-2.11.2
2.11.3
27/03/2026
Ultimate Member <= 2.11.1 – Reflected Cross-Site Scripting via Filter Parameters
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including, 2.11.1…
*-2.11.1
2.11.2
17/02/2026
Ultimate Member <= 2.11.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode attributes in all versions up to, and including, 2.11.0 due…
*-2.11.0
2.11.1
20/12/2025
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.11.0 – Unauthenticated Sensitive Information Exposure
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is…
*-2.11.0
2.11.1
19/12/2025
Ultimate Member <= 2.11.0 – Authenticated (Subscriber+) Profile Privacy Setting Bypass
The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and including, 2.11.0. This is due to a flaw in the secure fields mechanism where field keys are stored in…
*-2.11.0
2.11.1
16/12/2025
Ultimate Member <= 2.11.0 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'value'
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the YouTube Video 'value' field in all versions up to, and including, 2.11.0. This…
*-2.11.0
2.11.1
16/12/2025
Ultimate Member <= 2.10.3 – Authenticated (Administrator+) Arbitrary Function Call
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Arbitrary Function Calls in all versions up to, and including, 2.10.3. This is due to the plugin…
*-2.10.3
2.10.4
07/05/2025
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 – Unauthenticated Blind SQL Injection
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to blind SQL Injection via the search parameter in all versions up to, and including, 2.10.1 due to…
*-2.10.1
2.10.2
16/04/2025
Ultimate Member <= 2.10.0 – Unauthenticated SQL Injection via search Parameter
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 2.10.0 due to…
*-2.10.0
2.10.1
04/03/2025
Ultimate Member <= 2.9.2 – Authenticated SQL Injection
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping…
*-2.9.2
2.10.0
20/02/2025
Ultimate Member <= 2.9.1 – Unauthenticated SQL Injection
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions up to, and including, 2.9.1 due to…
*-2.9.1
2.9.2
17/01/2025
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 – Information Exposure
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses.…
*-2.9.1
2.9.2
17/01/2025
Ultimate Member <= 2.8.9 – Missing Authorization to Authenticated (Subscriber+) Arbitrary User Profile Picture Update
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and ajax_resize_image() functions in…
*-2.8.9
2.9.0
20/11/2024
Ultimate Member <= 2.8.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due…
*-2.8.6
2.8.7
03/10/2024
Ultimate Member <= 2.8.6 – Cross-Site Request Forgery to Membership Status Change
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or…
*-2.8.6
2.8.7
03/10/2024
Ultimate Member <= 2.8.4 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Skype and Spotify URL parameters in all versions up to, and including,…
*-2.8.4
2.8.5
10/04/2024
Ultimate Member <= 2.8.3 – Unauthenticated Stored Cross-Site Scripting
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 2.8.3 due to…
*-2.8.3
2.8.4
08/03/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.